OWASP
The Open Worldwide Application Security Project — a nonprofit foundation that works to improve software security through community-led open-source projects.
Definition
OWASP produces freely-available resources including the famous OWASP Top 10 (critical web application security risks), testing guides, cheat sheets, and security tools like OWASP ZAP. Founded in 2001, OWASP has become the de facto standard for application security. Their projects are vendor-neutral and community-driven.
Pourquoi c'est important
OWASP standards are referenced by major compliance frameworks including PCI DSS, HIPAA, and GDPR. The OWASP Top 10 is used by security teams worldwide as a baseline for secure development. Over 30% of Fortune 500 companies use OWASP resources.
Exemple
A development team uses the OWASP ASVS (Application Security Verification Standard) checklist to ensure their application meets security requirements before launch.